Directory Traversal Vulnerability in Agentejo Cockpit CMS
CVE-2018-15540

9.8CRITICAL

Key Information:

Vendor

Agentejo

Status
Vendor
CVE Published:
15 October 2018

What is CVE-2018-15540?

A vulnerability in Agentejo Cockpit CMS allows attackers to perform file system traversal, compromising the security of the application. This vulnerability enables malicious users to access and manipulate files outside the designated media directory, posing a significant risk to sensitive data. Improper validation mechanisms result in attackers being able to exploit this weakness, emphasizing the need for urgent patching and enhanced security measures.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.